Showing posts with label audit. Show all posts
Showing posts with label audit. Show all posts

Wednesday, March 12, 2014

Your Brother’s Keeper: the OCC & Third-Party Mortgage Vendor Relationships

Background

Nationally-chartered federal savings banks are subject to the prudential regulation of the Office of the Comptroller of the Currency (the “OCC”). National banks may engage in activities that are part of, or incidental to, the business of banking, or are otherwise authorized for a national bank. The business of banking is an evolving concept and the permissible activities of national banks similarly evolve over time.1 But when your bank’s senior management decides to outsource a critical function—especially a consumer-facing function like mortgage loan origination or servicing—you truly become your “brother’s keeper.” No Chief Executive Officer or Chief Compliance Officer wishes to find himself or herself targeted by the OCC for failure to conduct adequate third-party vendor due diligence or ongoing monitoring.

It had been historically understood that when employing third-party entities to conduct all or part of a critical banking function, by not fully understanding the nature of the risks being introduced to the bank and by not ensuring appropriate risk controls, senior management and boards of directors breach their most fundamental fiduciary responsibility to depositors and shareholders.2 The Federal Financial Institutions Examination Council (the “FFIEC”) very aptly highlights that although the technology needed to support business objectives is often a critical factor in deciding to outsource, managing such relationships is more than just a technology issue; it is an enterprise-wide corporate management issue.3

Long-standing OCC guidance

A national bank and its operating subsidiaries may make, purchase, sell, service, or warehouse house loans or other extensions of credit for its own or another’s account, including residential mortgage loans.4 A bank may conduct its mortgage operations in conjunction with a third-party not owned by the bank or bank holding company. Vendors, brokers, dealers, and agents can offer banks a variety of legitimate and safe opportunities to enhance product offerings, improve earnings, diversify assets and revenues, or reduce costs. In most instances the fundamental risks associated with activities introduced by third parties are no greater or less than the bank would have incurred had the bank performed the activity on its own.5

Historically, the OCC had very explicitly decreed that bank management cannot rely solely on third-party assertions, representations, or warranties when entering such relationships.6 Specifically, the OCC has long required that:

  • Before entering into a major relationship with a third party, a bank should establish a comprehensive program for managing the relationship.
  • Such programs should be documented and include front-end management planning, appropriate due diligence selecting a vendor, and performance monitoring.7

The requirements above were not merely satisfied by a bank relying solely upon its own internal Vendor Management Policy. The OCC expressly contemplated that the bank’s negotiators and signatories to the vendor contract would tailor the program to the specific vendor, and that the documentation would reflect the criteria and validation specific to that vendor with regard to the services for which the bank sought to contract.

OCC activity in the wake of Bulletin 2013-29

OCC treatment of third-party vendor risk management was recently further clarified when the agency issued Bulletin 2013-29: Third-Party Relationships - Risk Management Guidance on October 30, 2013.8  Among the OCC’s explicit guidance, the Agency deemed that an effective risk management process throughout the life cycle of the relationship includes:
·     plans that outline the bank’s strategy, identify the inherent risks of the activity, and detail how the bank selects, assesses, and oversees the third party;
·         proper due diligence in selecting a third party;
·         written contracts that outline the rights and responsibilities of all parties;
·         ongoing monitoring of the third party’s activities and performance;
·         contingency plans for terminating the relationship in an effective manner;
·       clear roles and responsibilities for overseeing and managing the relationship and risk management process;
·        documentation and reporting that facilitates oversight, accountability, monitoring, and risk management; and
·   independent reviews that allow bank management to determine that the bank’s process aligns with its strategy and effectively manages risks.

The OCC has wasted no time applying those third-party risk management principles immediately before and since the issuance of Bulletin 2013-29. On September 19, 2013, the OCC assessed a $60 million penalty against JPMorgan Chase and ordered the bank to reimburse consumers for unfair billing practices.9 In the JPMorgan Chase matter, the OCC order also requires the bank to take a number of corrective measures that include:
·         ensuring compliance with the FTC Act;
·   improving governance of third-party vendors associated with certain consumer products;
·    developing an enterprise-wide risk management program for such consumer products marketed or sold by the bank or its vendors; and
·         improving its consumer compliance internal audit program.

American Express Bank received an early Christmas present, when the OCC announced on December 24, 2013 that it would assess a $3 million penalty against the bank and order restitution to customers for unfair billing and deceptive marketing practices.10 The OCC order, whose restitution payments also satisfied related Consumer Financial Protection Bureau (CFPB) obligations, requires the bank to:
·  improve governance of third-party vendors associated with “add-on” consumer products;
·     develop a risk management program for “add-on” consumer products marketed or sold by the bank or its vendors; and
·    conduct an “add-on” product review to, among other things, identify and remediate consumer harm and any program weaknesses.

The OCC has clearly communicated that it intends to aggressively protect consumers from harmful activities resulting from a bank’s use of third-party vendors, and that it will hold a bank fully responsible for that third party’s missteps.

Critical Attention to Pre-Contractual Due Diligence

Every activity undertaken by bank management and its agents should accord with OCC requirements, and support subsequent examination by the OCC, the internal audit function, and external auditors. The contemplation of a significant third-party business relationship that contributes directly to a bank’s growth plan should be disclosed in sufficient detail by bank management to the bank’s board of directors to facilitate the board’s fiduciary responsibility. Negotiators of a third-party business relationship (inclusive of bank management, holding company management, and legal counsel) are in the best position to review, inquire, and edit contract provisions accordingly prior to execution to ensure that all contract provisions directly address OCC compliance requirements, including those relating directly to third-party risk and due diligence.

With reliance upon bank management and its agents who engage directly in the planning, negotiation, and execution of the third-party agreement, one should reasonably be able to conclude that those parties have conducted their activities in accordance with OCC Bulletin 2013-29.11 In advance of executing an agreement, bank management and its agents would have engaged in and fully documented both management planning and due diligence in selecting a vendor. The agreement would further have documented the ongoing performance monitoring required to evaluate the ongoing vendor risk management posture. To have failed to faithfully adhere to the details of the Bulletin by simply relying upon professional relationships or contractual representations and warranties would be both imprudent and discordant with explicit OCC guidance.

Ongoing Risk Assessment and Improved Governance

If a CEO or CCO had not been involved in contract negotiations with a third-party vendor, then that leader may not be able to independently confirm whether or not bank management and its agents adhered to OCC requirements during the pre-contractual due diligence period. Once that leader becomes aware that such a gap may have occurred, it becomes incumbent upon that leader to undertake an independent risk assessment of the third-party vendor relationship. This obligation becomes critically important when the third-party vendor is providing consumer mortgage loan services.

The auditors assigned to conduct the independent third-party risk management review should be able to request, obtain and evaluate pre-contractual documentation, and supplement their initial conclusions with interviews with the individuals directly engaged in the planning, negotiation, and execution of the third-party vendor agreement. As with any audit, should the auditors identify exceptions to the OCC’s third-party risk management guidelines that present a material risk of non-compliance or future financial loss, then in accordance with the Chief Audit Executive, you would advise that bank management and the bank board be so advised that subsequent remedial measures be undertaken.

Conclusion

It is evident that the OCC expects governance, risk management, and controls (GRC) to be in place prior to and at the inception of third-party mortgage vendor relationships. Even as bank management remediates the existing relationship with a consumer mortgage vendor, all stakeholders should take note of the lessons learned from a less-than-thorough due diligence; explicit contractual role definition; and contractual provisions for detailed oversight, accountability, and monitoring. Future third-party vendor relationships must incorporate those onboarding elements as standard requirements of a larger enterprise-wide risk management process, lest the OCC surmise that your bank’s governance practices are insufficient to take heed of Bulletin 2013-29.


References





5      Third-Party Risk, August 29, 2000. (Subsequently rescinded by OCC Bulletin 2013-29)

6      Ibid.






Sunday, January 26, 2014

Starving for Compliance? Bring your Risk Appetite

“If it's your job to eat a frog, it's best to do it first thing in the morning. And if it's your job to eat two frogs, it's best to eat the biggest one first.”  ~Mark Twain
 

As Audit, Compliance & Ethics professionals, it is often our job to “eat a frog” and you likely find yourself sitting down to a banquet of frogs when crisis strikes your organization. Some of us consciously chose to enter the AC&E profession, while others with whom I’ve spoken tell me how their roles morphed into compliance functions. Either way, once we’ve accepted the responsibility to safeguard our organization’s enterprise risk management program, we must faithfully deploy an appropriate compliance framework.
One cannot simply purchase a compliance program at an online retailer, download it to your tablet, and check that task off your list. There is no one-size-fits-all compliance program that is going to align perfectly with every organization’s ERM model. The design of the compliance program begins with a studied understanding of the organization’s risk appetite. Delivering an off-the-shelf or generic compliance program to an organization without factoring in its risk appetite is like delivering a freeze-dried meal to a guest’s table without inquiring of her culinary preferences.

Risk appetite is that level of risk that an organization is prepared to willingly accept before mitigating actions are required to reduce it. Formulating the risk appetite requires the Board of Directors to consciously identify its consensus balance between the anticipated benefits of a chosen course of action and the threats that an uncertain future inevitably brings. Each area of risk may enjoy differing risk appetites. For instance, a well-capitalized organization bearing a trusted brand may be more averse regarding reputation and litigation risks, but more inclined to accept a moderate degree of financial and strategic risks. Such may be the variations found also in compliance risk appetites.
A compliance purist—if such a person exists—would trend strongly toward risk aversion. A Gordon Gekko (credit to Oliver Stone’s “Wall Street” fame) would trend strongly toward risk hunger. Since compliance is not generally viewed as a profit center, a typical organization’s Board of Directors will formulate a compliance risk appetite that represents its view of an appropriate balance (i.e. expects ethical business conduct that achieves its mission). A publicly-traded company may seek to maximize shareholder value and profit, but likely seek to avoid criminal and civil prosecution. A non-profit organization may seek to maximize its impact serving the largest number of people in a community, but likely seek to minimize its administrative cost ratio and excessive CEO compensation.

Organizations that design, employ, and monitor compliance programs that align with the Board of Directors’ risk appetite will encounter fewer compliance failures over the long-term. I am careful to point out that all organizations, no matter how well-run, will experience a compliance failure at some time. A risk appetite acknowledges that while risk may be mitigated, it generally cannot be entirely eliminated. To eliminate all risk is to forgo meaningful opportunities that competing organizations would be willing to accept, thus neutralizing your organization’s effectiveness in the space in which it competes. This fact does not apply only to for-profit companies, because non-profit organizations also compete for scarce resources and relevancy. Risk must always be recognized as a factor to be managed.
Whether you are designing a new program or enhancing an existing compliance program, you will want to ascertain your organization’s defined compliance risk appetite. Your compliance program, including training, monitoring, and Board-level reporting, must align to that risk appetite to provide appropriate risk management tools to support your organization. Finally, periodically revisit the relationship between the stated risk appetite and your program elements to ensure that you are making appropriate adjustments.

Don’t starve your compliance program. Embrace the risk appetite. Be prepared to one day confidently defend your compliance risk management program to your external auditors and prudential regulators…and enjoy that frog sooner than later.

Tuesday, November 5, 2013

Regulatory Compliance: Tear Down That Ivory Tower!

I recently ran into a Compliance colleague, “Jill”, whom I hadn’t seen in a while. As we exchanged pleasantries, Jill explained how busy she has been at her organization, to a point where she “couldn’t even get out of her office for lunch most days.” I understood her sentiment, but I challenged Jill’s premise that her most effective oversight of her Compliance Management Program was being accomplished sitting at her desk with her nose to the proverbial grindstone.

“What do you mean?”, Jill inquired.

“For starters, how are you assessing the compliance culture within and across your organization?”, I responded. I waited for the predictable response.

“I receive reports from each department head on a quarterly basis. I meet with those same department heads at least annually as we update our risk assessment. “ And then she punctuated her response, “I always know what is going on from a Compliance perspective.”

We visited for a few more minutes before continuing on our respective journeys. I have the utmost respect for Jill, and the many colleagues with whom I’ve engaged in similar conversations over the years. But I was reminded again that day that differing viewpoints pervade our Compliance Management profession.

I liken the practice of our craft to that of a world traveler. In fact, given the international nature of Regulatory Compliance, many of us have become world travelers from time to time. But one cannot truly experience traveling the world by reading other people’s written accounts of foreign lands. Similarly, Compliance professionals cannot simply read stacks of reports, formally engage depart heads once or twice annually, and conclude that they have traveled the organizational “globe”.

We’ve got to come down out of our ivory towers. In fact, we’ve got to tear down our ivory towers in the Compliance Department and never return to our old ways. Instead, let’s engage leaders at all levels across our organizations as often as possible. Informal dialogue that may occur within the context of a scheduled project meeting, or a chance meeting in the hallway, can often generate useful information that lends itself well to a holistic risk assessment.

Leaders want to tell you what concerns they are facing, and when those concerns signal regulatory compliance exposure, you have an opportunity to collaborate further toward a resolution. Internal Audit provides another natural source of regulatory compliance risk data gleaned from its expansive reach throughout your organization. Regulatory Compliance also finds a natural ally in the Information Technology Department, where governance, risk management and compliance looms large over an ever-evolving landscape. Compliance professionals grow to become trusted confederates with leaders of lines of business, Internal Audit and Information Technology.

So join me! Grab your water bottle or coffee cup, and explore your organization more freely. Engage others daily and take a more genuine interest in the regulatory compliance challenges facing your fellow leaders. Collaborate with them to develop lasting compliance solutions. Your risk assessments and resultant regulatory compliance program will flourish, producing more meaningful results for the entire organization. You won’t want to return to the ivory tower.

Friday, October 11, 2013

WHEN ETHICS AND EXPEDIENCY COLLIDE

“It is the mark of an educated mind to be able to entertain a thought without accepting it.” ~Aristotle

“There are no easy answers' but there are simple answers. We must have the courage to do what we know is morally right.” ~Ronald Reagan


As Compliance and Ethics Professionals, we are daily reminded that violations of law and dignity are no less common now than they were in ancient civilizations. We report upon and read about corporate, government, and personal scandals that boggle the mind. Acts and omissions that defy common sense are nonetheless undertaken out of expediency, greed and ignorance, only to eventually expose the perpetrators in the public square.

Why?

Why--with all the failed historical examples, complex laws, regulatory bodies, education and training—do some organizations continue to succumb to poor judgment and wrongdoing, while other organizations rise above?

While we speak often about the ‘tone at the top’, we must also acknowledge that ideas and actions emanate at all levels of our organizations. Driven by deadlines, profits, corporate goals, marketplace competition, etc., individuals contemplate ideas and execute upon those ideas. But not all ideas for generating revenue, decreasing expenses, or streamlining processes merit the same consideration.

An organization’s culture, modeled by its leaders at all levels, must unambiguously communicate that execution must meet its values. A healthy exchange of ideas should always be weighed sufficiently and transparently by knowledgeable stakeholders, so as to expose potential ethical, legal and financial pitfalls. Though we are charged with educating our operational and administrative colleagues about our Code of Conduct and our Legal and Regulatory obligations, we have the additional obligation to actively counsel them as well.

Leveraging our Anonymous Reporting Hotlines, Internal Audit Departments, and industry and regulatory trends, we ourselves must be prepared to actively engage our colleagues across our organizations to probe for prospective lapses. In a highly-charged competitive environment, we cannot idly sit by and fail to question if expediency is trumping ethical decision-making. Let’s not forget that we are the protagonists—not the villains—in this story.

Thursday, March 28, 2013

Enterprise Risk Management: Captain Kirk Confronts the Final Frontier

When faced with the regulatory mandate to incorporate or improve your organization's enterprise (or enterprise-wide) risk management (ERM) process, we can sometimes feel like a Klingon confronting Tribbles. To succeed with ERM within our organization, we must instead adopt the attitude expressed by Captain James Kirk in the'Day of the Dove episode: "There's another way to survive. Mutual trust...and help."
Several years ago, the federal banking regulators set off on a mission to bring Enterprise Risk Management (ERM) to the forefront of financial institution governance expectations. In the ensuing years, state insurance regulators have joined the mission through the National Association of Insurance Commissioners (NAIC) Own Risk and Solvency Assessment (ORSA) model act. The topic continues to get considerable attention in recent regulatory guidance, including Federal Reserve Board (FRB) supervisory letters 12-7 and 08-8. The Federal Reserve Bank of Chicago (FRB-C) devoted considerable attention to the topic at its 2011 conference.

What appeared to be a distant risk management galaxy in the late 1990s has certainly become an oft-discovered governance imperative for financial institutions. As a financial industry executive, you know that you have been charged with the responsibility “to boldly go where no man has gone before.” Much like the voyage of the storied U.S.S. Enterprise, your voyage has taken you to strange new worlds as you have sought to develop or improve your ERM model.

When you have set out to build a robust risk management infrastructure to integrate, coordinate and facilitate forward-looking risk management throughout the enterprise, you invariable have encountered (or will encounter) skeptics. Captain Kirk addressed this challenge in the 'A Private Little War' episode: "The only solution is...a balance of power. We arm our side with exactly that much more. A balance of power...the trickiest, most difficult, dirtiest game of them all. But the only one that preserves both sides."
But make no mistake about it—ERM is not optional and is here to stay. Thus, we often will find ourselves educating senior leadership colleagues and independent directors about ERM, in parallel with obtaining the necessary data to build, enhance, and report upon our ERM model. ERM cannot simply become a once-and-done exercise that ends up on a binder on your credenza.

Building a culture around ERM involves acclimating leadership throughout the organization to a continuous reporting system that identifies and addresses emerging risks. Strategic initiatives and ongoing business planning are evaluated in light of current and emerging risks and incorporated into analysis and leadership and board decision-making. ERM becomes a discussion item on at least a weekly basis within the leadership team, and a standing agenda item for your board, often through an ERM committee. Reports are designed to be condensed, accurate and meaningful for decision-making.

Internal Audit and Compliance play key roles in the ERM process. The periodic review and validation of the model through targeted risk assessments must be conducted under the direction of the organization’s senior leadership to support the organization’s risk appetite.

Occasionally, Captain Kirk and his officers would find themselves enmeshed in a scene from Earth's pre-space travel history, yet the episode always ended with our beloved travelers safely back aboard the U.S.S. Enterprise. As your ERM model and methodology evolve, it is likely that the organization will also never return by the way that it arrived, because external variables will continually infiltrate the ERM model. Most notably, your organization’s ERM will remain under the scrutiny and be subject to the recommendations of your prudential regulator. There simply is no going back.

Continue to be the evangelist for sound enterprise risk management in your organization, devoting yourself to encouraging, educating and embracing your colleagues as you faithfully fulfill the ERM governance role entrusted to you. Much like Kir, may you live long and prosper in your role.

Wednesday, March 6, 2013

Strength and Sustainability: Collaborative Compliance Amidst Complexity

I simply do not have all of the answers. There, I have said it.
My simple statement sums up the collective admission of Compliance, Audit and Ethics professionals globally. The annual proliferation of domestic and international regulatory requirements continues to proceed at an ever increasing rate. When only a decade or two ago, a chief compliance officer might likely have understood the details of all regulatory responsibilities within his/her realm, many of us have now grown accustomed to reliance upon specialized colleagues to identify the details of specific branches within our own compliance universe. At least two easily recognizable trends have led to this reality: global commerce and systemic failure.
Global commerce has both driven and benefited from technological and economic advances throughout history. Progressing beyond the steamships that replaced clipper ships, the internet built upon the initial success of the transoceanic cables laid long ago. While local trade rules and customs remain, the international Law of the Sea has been joined by International Free Trade Agreements and transcontinental legal structures, most notably the European Union, where supranational legal structures both supplant and co-exist with domestic laws and regulations.
Systemic failures that have led to financial crises within nations as diverse as Greece, Ireland, Japan and the United States have resulted in the now-familiar remedies of International Monetary Fund austerity measures, the Third Basel Accord, and Dodd-Frank  Wall Street Reform and Consumer Protection Act, to name a few examples. Regulators have sought to eliminate pathways to fraud, largess and market manipulation widely blamed for the global crises by promulgating lengthy and complex regulatory solutions.
Compliance professionals who once may have laid claim to comprehending and administering compliance programs involving an entire continent or nation have succumbed to a level of regulatory complexity that makes such independent mastery incomprehensible. Even for those of us who oversee primarily domestic compliance programs, international influences are now omnipresent in Dodd-Frank, the Bank Secrecy Act, FCPA and the U.K. Bribery Act of 2010.
At the end of the day, Compliance, Audit and Ethics professionals are exactly that—professionals. We do not simply throw our hands up and decry the unfairness of increasingly complex regulatory requirements. True to our nature, we seek to understand as much as possible about our responsibilities to fulfill those compliance requirements in conjunction with our organization’s core mission and objectives. But our inquiries and information gathering must extend beyond our own individual knowledge and planning. Today’s increasingly complex regulatory environment requires us to collaborate with colleagues both within our organizations and beyond.
I would propose that now is the time to build stronger, more sustainable Compliance Programs through intelligent collaboration. It must not be viewed as a sign of ignorance or laziness when we humbly and actively partner with fellow Compliance, Audit and Ethics professionals to ascertain best practices. Likewise, we must continue to embrace the business line leaders within our own organizations to build collaborative compliance solutions that fulfill our regulatory responsibilities without unnecessarily impeding daily operations and long-term strategies.
Effective Regulatory Compliance…we may not each be able to do it alone, but we can certainly do it more constructively together.

Monday, February 11, 2013

COMPLIANCE NEVER SLEEPS

Ever so slowly a consensus appears to be emerging that the economy has been improving in the United States. Though some economic indicators, including the unemployment rate and consumer sentiment, remain stagnant, we are witnessing a rebound in private sector hiring, new construction, and equities investing. Equity is returning to homeowners and mortgage refinancing has returned. Innovation continues to flourish across industries.
And the imperative for vigilant corporate compliance programs and professionals has never been greater.
Lest you brand me a killjoy at the party of renewed American prosperity, let me encourage you to pause and reflect upon the post-recessionary periods of the past several decades.
When organizations emerge from the austerity and uncertainty of a recession, like action movie survivors emerging from a post-apocalyptic underground bunker, leaders seek to return to the familiar and comfortable patterns of pre-recession growth. We want to sell things. We want to build things. We hire people and purchase systems and tools to do both. And we want to do it quickly to make up for lost time and to satisfy pent-up consumer demand.
I propose that, as leaders, we should also pause to reflect upon the patterns and practices that led to the recession in the first place. On a microeconomic level, the organizations whose actions precipitated the recessionary events often succumbed to false notions of success built upon skewed compensation plans, short-term corporate financial results, and process or quality breakdowns. While the industries may change from financial crisis to financial crisis, the factors that string the past two decades’ mortgage banking, energy trading, and technology busts together are not very dissimilar.
So, what is the difference between the company that succumbs and the company that succeeds over the long term in the very same industry? I would conclude that it rests upon universal adherence to an unwavering compliance program. Like guardians at the gate, the joint efforts of Compliance, Audit, Security, and Ethics professionals stand firm against cultural shifts within some organizations that allow foundations to crack.
As we move beyond this most recent recession into our blossoming period of prosperity, I encourage you to take a moment to re-evaluate your investment in your organization’s compliance program. Even as you bolster production and sales efforts to meet consumer demand, bolster compliance resources within the organization.
·         Publicize your Code of Conduct and Ethics Hotline.
·         Revisit traditional and emerging high-risk areas of compliance and control exposure.
·         Renew your leadership commitment to the truth that your corporate compliance program is a competitive advantage.
Preparing your compliance program today to withstand the inevitable recession of tomorrow will ensure long-term prosperity for your organization.

Monday, September 19, 2011

REGULATORS, AUDITORS AND EXAMINERS --OH MY!

Q: What do you get if you cross a wild, ferocious, man-eating tiger with an internal auditor?
A: A dull tiger.


OK, by a show of hands, how many of you are excited when you receive the audit engagement letter or regulatory exam notification? Do you mark the dates on your calendar with the same enthusiasm with which you block off your two-week mid-winter Caribbean vacation?

Given what I've observed over the years, I think not. I am here to suggest that we can and should embrace those individuals entrusted with auditing and examining our Organizations--and, no, I have not lost my good sense.

I recall my days as a bank auditor, when my arrival on site appeared to suck the joy right out of the room. Mind you, in hindsight I can humbly admit that the process owners certainly knew their craft far better and more realistically than my well-studied audit manuals could have prepared me. And while I and many of my fellow auditors throughout history have long sought to conduct dispassionate audits with collegial objectivity, management frustration often bubbled just below the surface, bursting forth as certain numbered comments touched unforeseen raw nerves.

The passing of years witnessed my migration away from the internal audit function toward the risk management function via a brief passage through a regulatory agency. At each stage, I tried to bring all perspectives together into one cohesive approach to audits and regulatory exams. I do not believe that I am alone in this regard, as many Leaders more experienced than me have found themselves reconciling multiple facets of the audit/exam process throughout our careers.

What I find fascinating is how many otherwise well-balanced, seasoned Leaders bristle at the notion that they could learn from--let alone seriously consider--the noted exceptions or discussed observations during an operational audit or regulatory examination. The very same Leaders who would pay consultants handsomely to deconstruct and reorganize entire Divisions within the Organization, or who engage high-end vendors to supplant legacy technology with enterprise solutions, will balk at the suggestion that a professional committed to assuring the safety and soundness of the Organization would be any less committed to objective and sustainable improvement.

I am certainly not suggesting that we butter up, befriend or brown nose the independent auditor or government regulator charged with overseeing the thorough examination of our Organizations. I am suggesting that we, as Leaders, owe our Organizations a fiduciary duty to approach the audit/exam with an open mind and a willingness to accept that--despite our best efforts--our Teams could be performing one or more functions with greater care. Unlike the consultants and vendors we hire, our auditors and regulators are not primarily driven by a profit motive or to extract repeat business.

My first-hand experience with administering audits, especially those supported by early warning systems, was to (1) gain a better understanding of the operational processes; (2) identify remedies that had been made to previously-identified exceptions; and (3) offer best practice guidance and foreshadowing of regulatory effects that would impact the process owner's area of responsibility. Our Audit Team certainly wasn't there to one-up management or disrupt well-functioning operations.

On the Risk Management side, despite others' tendencies to view regulatory examinations as declarations of war against the various Organizations, I sought to assume the best intentions. Though it comes as a shock to some, I generally received what I had assumed: professional auditors/examiners (a) conducting objective assessments; (b) examining and documenting the sufficiency of mitigating controls; and (c) offering improvements supported either by industry best practices or foretellings of regulatory rule making. And although I had observed other Leaders come to blows in heated battle with examiners, I never found myself in that adversarial position.

We will all certainly continue to look forward to that two-week mid-winter Caribbean jaunt with much more excited anticipation than any audit or regulatory exam, but as Leaders we can certainly adopt a more collegial and consultative approach to those periodic and foreseeable occasions. You won't be disappointed.